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Amended claims follow: 

1. (currently amended) A computer program product operable to control an e-mail 
client computer to detect e-mail propagated malware, said computer program product 
comprising: 

e-mail generating logic operable to generate an e-mail message; 

comparison logic operable to compare said e-mail message with at least one of an 
address book of a sender of said e-mail message and one or more previously generated e- 
mail messages from said client computer; and 

identifying logic operable to identify said e-mail message as potentially 
containing malware if at least one of: 

(i) said e-mail message is being sent to more than a threshold number of 
addressees specified within said address book; 

(ii) said e-mail message contains message content having at least a 
threshold level of similarity to non-identical m essage content of said previously 
generated e-mail messages being sent to more than a threshold number of addressees 
specified within said address book; and 

(iii) said e-mail message contains message content having at least a 
threshold level of similarity to non-identical m essage content of more than a threshold 
number of said previously generated e-mail messages; and 
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quarantine queue logic operable to hold said previously generated e-mail 
messages in a quarantine queue for at least a predetermined quarantine period prior to 
being sent from said client computer. 

2. (original) A computer program product as claimed in claim 1 3 wherein said e- 
mail message specifies a plurality of addressees, said comparison logic being operable to 
compare said plurality of addressees with said e-mail address book to determine if said at 
least a threshold number of addressees has been exceeded. 

3. (original) A computer program product as claimed in claim 1, wherein said at 
least a threshold number of addressees is specified as a proportion of addressees within 
said address book. 

4. (original) A computer program product as claimed in claim 3, wherein said 
proportion of addressees within said address book is user specified. 

5. (cancelled) 

6. (currently amended) A computer program product as claimed in claim [5] 
wherein said quarantine period is user specified. 

7. (original) A computer program product as claimed in claim 1, comprising 
confirmation input logic operable when said e-mail message is identified as potentially 
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containing malware to generate a user message seeking a confirmation input from a user 
of said client computer before said e-mail message is sent. 

8, (original) A computer program product as claimed in claim 1 > comprising 
administrator warning logic operable when said e-mail message is identified as 
potentially containing tnalware to send an administrator warning message to an 
administrator of said client computer regarding said e-mail message. 

9. (currently amended) A method of detecting e-mail propagated malware within 
an e-mail client computer, said method comprising the steps of: 

generating an e-mail message; 

comparing said e-mail message with at least one of an address book of a sender of 
said e-mail message and one or more previously generated e-mail messages from said 
client computer; 

identifying said e-mail message as potentially containing malware if at least one 

of: 

(i) said e-mail message is being sent to more than a threshold number of 
addressees specified within said address book; 

(ii) said e-mail message contains message content having at least a 
threshold level of similarity to non-identical m essage content of said previously 
generated e-mail messages being sent to more than a threshold number of addressees 
specified within said address book; and 
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(iii) said e-mail message contains message content having at least a 
threshold level of similarity to non-identical m essage content of more than a threshold 
number of said previously generated e-mail messages; and 

holding said previously generated e-mail messages in a quarantine queue for at 
least a predetermined quarantine period prior to being sent from said client computer. 

10. (original) A method as claimed in claim 9, wherein said e-mail message 
specifies a plurality of addressees* said plurality of addressees being compared with said 
e-mail address book to determine if said at least a threshold number of addressees has 
been exceeded 

1 1 . (original) A method as claimed in claim 9, wherein said at least a threshold 
number of addressees is specified as a proportion of addressees within said address book. 

12. (original) A method as claimed in claim 11, wherein said proportion of 
addressees within said address book is user specified. 

13. (cancelled) 

14. (currently amended) A method as claimed in claim [13]9, wherein said 
quarantine period is user specified. 
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15. (original) A method as claimed in claim 9, wherein when said e-mail message 
is identified as potentially containing malware, then a user message is generated seeking 
a confirmation input from a user of said client computer before said e-mail message is 
sent, 

16. (original) A method as claimed in claim 9, wherein when said e-mail message 
is identified as potentially containing malware, then an administrator warning message is 
sent to an administrator of said client computer regarding said e-mail message. 

17. (currently amended) Apparatus for detecting e-mail propagated malware 
within a client computer, said apparatus comprising: 

an e-mail generator operable to generate an e-mail message; 

a comparitor operable to compare said e-mail message with at least one of an 
address book of a sender of said e-mail message and one or more previously generated 
mail messages from said client computer; 

a malware identifier operable to identify said e-mail message as potentially 
containing malware if at least one of: 

(i) said e-mail message is being sent to more than a threshold number of 
addressees specified within said address book; 

(ii) said e-mail message contains message content having at least a 
threshold level of similarity to non-identical m essage content of said previously 
generated e-mail messages being sent to more than a threshold number of addressees 
specified within said address book; and 
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(iii) said e-mail message contains message content having at least a 
threshold level of similarity to non-identical message content of more than a threshold 
number of said previously generated e-mail messages; and 

a quarantine queue operable to hold said previously generated e-mail messages in 
a quarantine queue for at least a predetermined quarantine period prior to being sent from 
said client computer. 

18. (original) Apparatus as claimed in claim 17, wherein said e-mail message 
specifies a plurality of addressees, said comparitor being operable to compare said 
plurality of addressees with said e-inail address book to determine if said at least a 
threshold number of addressees has been exceeded. 

19. (previously presented) Apparatus as claimed in claim 17, wherein said at least 
a threshold number of addressees is specified as a proportion of addressees within said 
address book. 

20. (original) Apparatus as claimed in claim 19, wherein said proportion of 
addressees within said address book is user specified, 

21. (cancelled) 

22. (currently amended) Apparatus as claimed in claim [21] 17, wherein said 
quarantine period is user specified. 
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23. (original) Apparatus as claimed in claim 17, comprising a confirmation input 
unit operable when said e-mail message is identified as potentially containing malware to 
generate a user message seeking a confirmation input from a user of said client computer 
before said e-mail message is sent 

24. (original) Apparatus as claimed in claim 17, comprising an administrator 
warning unit operable when said e-mail message is identified as potentially containing 
malware to send an administrator warning message to an administrator of said client 
computer regarding said e-mail message. 
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